UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Security & Risk Analysis

wordpress.org/plugins/uichemy

Convert Figma to WordPress, Elementor, Gutenberg & Bricks. Design in Figma, Import to WordPress. 100% Editable. No Code. No Rebuild. 80,000+ users.

9K active installs v4.7.3 PHP 7.4+ WP 6.6+ Updated Mar 26, 2026
figma-to-bricksfigma-to-codefigma-to-elementorfigma-to-gutenbergfigma-to-wordpress
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 12, 2026
Safety Verdict

Is UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Safe to Use in 2026?

Generally Safe

Score 98/100

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jan 12, 2026Updated 1mo ago
Risk Assessment

The uichemy plugin v4.7.0 exhibits a generally good security posture due to its adherence to several security best practices, including the consistent use of prepared statements for SQL queries and a high percentage of properly escaped output. The presence of nonce and capability checks on all identified AJAX entry points is also a positive indicator. However, the static analysis reveals a significant concern with the presence of the `unserialize` function, which, if used with user-supplied input, can lead to critical remote code execution vulnerabilities. While the taint analysis did not flag critical or high severity issues, the two identified unsanitized path flows warrant attention as they could potentially be exploited in conjunction with other weaknesses. The vulnerability history, though showing no currently unpatched CVEs, indicates a past pattern of medium severity vulnerabilities including Cross-site Scripting and Missing Authorization, suggesting a need for continued vigilance and thorough auditing.

In conclusion, while uichemy v4.7.0 demonstrates strengths in fundamental security areas like output escaping and database query sanitization, the critical risk posed by the `unserialize` function and the potential for unsanitized path flows, coupled with its historical vulnerability profile, necessitates a cautious approach. The absence of unpatched CVEs is encouraging, but the underlying code signals and past incidents suggest that further review and potentially remediation of the `unserialize` usage are crucial for a robust security posture.

Key Concerns

  • Dangerous function 'unserialize' detected
  • Taint analysis found unsanitized paths
  • History of medium severity vulnerabilities
Vulnerabilities
2 published

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-69362medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

UiChemy <= 4.4.2 - Authenticated (Author+) Stored Cross-Site Scripting

Jan 12, 2026 Patched in 4.4.3 (8d)
CVE-2025-62013medium · 4.3Missing Authorization

UiChemy <= 4.0.0 - Missing Authorization

Oct 16, 2025 Patched in 4.0.1 (8d)
Version History

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Release Timeline

v4.7.3Current
v4.7.2
v4.7.1
v4.7.0
v4.6.0
v4.5.0
v4.4.3
v4.4.21 CVE
v4.4.11 CVE
v4.4.01 CVE
v4.3.01 CVE
v4.2.01 CVE
v4.1.21 CVE
v4.1.11 CVE
v4.1.01 CVE
v4.0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Code Analysis

Dangerous Functions
6
Raw SQL Queries
0
4 prepared
Unescaped Output
1
102 escaped
Nonce Checks
10
Capability Checks
15
File Operations
1
External Requests
6
Bundled Libraries
0

Dangerous Functions Found

unserialize$elementor_plugin = unserialize(wp_remote_retrieve_body($response));includes\admin\class-uich-api.php:1655
unserialize$tpgb_plugin = unserialize(wp_remote_retrieve_body($response));includes\admin\class-uich-api.php:1843
unserialize$plugin_info = unserialize( wp_remote_retrieve_body( $response ) );includes\admin\class-uich-enqueue.php:352
unserialize$old_value = unserialize(serialize($global_classes));;includes\admin\globals\class-uich-atomic-globals.php:99
unserialize$old_value = unserialize(serialize($global_classes));includes\admin\globals\class-uich-atomic-globals.php:348
unserialize$old_value = unserialize(serialize($global_classes));includes\admin\globals\class-uich-atomic-globals.php:371

SQL Query Safety

100% prepared4 total queries

Output Escaping

99% escaped103 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
uich_api_call (includes\admin\class-uich-api.php:1589)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 10

authwp_ajax_uich_regenerate_tokenincludes\admin\class-uich-api.php:79
authwp_ajax_uich_select_userincludes\admin\class-uich-api.php:80
authwp_ajax_uich_uichemyincludes\admin\class-uich-api.php:81
authwp_ajax_elementor_import_mediaincludes\admin\class-uich-atomic-imgs.php:7
authwp_ajax_uich_bricks_import_mediaincludes\admin\class-uich-bricks-imgs.php:3
authwp_ajax_uichemy_import_imagesincludes\admin\class-uich-copy-images.php:42
authwp_ajax_uich_install_wdesignincludes\admin\class-uich-enqueue.php:48
authwp_ajax_uich_boarding_storeincludes\admin\class-uich-enqueue.php:50
authwp_ajax_uich_activate_elementor_pro_pluginincludes\admin\class-uich-enqueue.php:66
authwp_ajax_uich_update_notice_countincludes\admin\class-uich-enqueue.php:68
WordPress Hooks 25
filterrest_pre_serve_requestincludes\admin\class-uich-api.php:75
filterupload_mimesincludes\admin\class-uich-api.php:76
filterhttp_request_timeoutincludes\admin\class-uich-api.php:77
filteruich_recommended_settingsincludes\admin\class-uich-api.php:83
actionrest_api_initincludes\admin\class-uich-api.php:85
actionelementor/initincludes\admin\class-uich-elementor.php:40
actionelementor/element/common/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:51
actionelementor/element/section/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:52
actionelementor/element/column/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:53
actionelementor/element/container/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:54
actionelementor/element/parse_cssincludes\admin\class-uich-elementor.php:56
actionelementor/editor/after_enqueue_scriptsincludes\admin\class-uich-elementor.php:58
actionadmin_menuincludes\admin\class-uich-enqueue.php:38
actionadmin_enqueue_scriptsincludes\admin\class-uich-enqueue.php:39
actionwp_enqueue_scriptsincludes\admin\class-uich-enqueue.php:40
actionenqueue_block_editor_assetsincludes\admin\class-uich-enqueue.php:43
actionadmin_enqueue_scriptsincludes\admin\class-uich-enqueue.php:46
actionadmin_headincludes\admin\class-uich-enqueue.php:52
actionelementor/editor/after_enqueue_scriptsincludes\admin\class-uich-enqueue.php:70
actionwp_loadedincludes\admin\class-uich-enqueue.php:75
actionwp_headincludes\admin\class-uich-enqueue.php:76
filteruich_manage_tokenincludes\admin\class-uich-token-manager.php:35
filteruich_manage_usermanagerincludes\admin\class-uich-usermanager.php:34
actionplugins_loadedincludes\class-uich-uichemy.php:63
filterplugin_row_metaincludes\notices\class-uich-plugin-page.php:68
Maintenance & Trust

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version7.4
Downloads131K

Community Trust

Rating100/100
Number of ratings13
Active installs9K
Developer Profile

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Developer Profile

POSIMYTH

8 plugins · 461K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
92 days
View full developer profile
Detection Fingerprints

How We Detect UiChemy — Figma Converter for Elementor, Gutenberg and Bricks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uichemy/assets/css/uichemy.css/wp-content/plugins/uichemy/assets/js/uichemy-frontend.js/wp-content/plugins/uichemy/assets/js/uichemy-backend.js/wp-content/plugins/uichemy/assets/js/uich-elementor-editor.js
Script Paths
/wp-content/plugins/uichemy/assets/js/uichemy-frontend.js/wp-content/plugins/uichemy/assets/js/uichemy-backend.js/wp-content/plugins/uichemy/assets/js/uich-elementor-editor.js
Version Parameters
uichemy/assets/css/uichemy.css?ver=uichemy/assets/js/uichemy-frontend.js?ver=uichemy/assets/js/uichemy-backend.js?ver=uich-addons-editor-js?ver=

HTML / DOM Fingerprints

CSS Classes
uich-containeruich-item
HTML Comments
UiChemy : Custom CSS
Data Attributes
data-uich-iddata-uich-type
JS Globals
window.uich_frontend_settings
REST Endpoints
/wp-json/uich/v2/uich_store_user_data
FAQ

Frequently Asked Questions about UiChemy — Figma Converter for Elementor, Gutenberg and Bricks